Showing posts with label micro SD security card. Show all posts
Showing posts with label micro SD security card. Show all posts

Friday, January 17, 2014

Secfone beyond encrypted mobile communication - Key protection



A recent blog post on the impacts of Snowden's leaded documents on encryption softwares skyrocketed on this blog. Thanks folks!

However several questions came up concerning Secfone's solution let me answer them here. I try not to be too technical, so it will be understandable for non-infosec users too.

How Secfone protects encryption keys?

One of the fundamental issues in communication encryption is how the solution protects the encryption keys. If the keys are compromised, than the communication can easily be tapped. Encryption softwares can use only the device's (smartphone) store and CPU to store, generate, manage and use encryption keys. However these hardware elements are not designed to protect anything. This is one of the biggest weak-point of all encryption software.

Secfone uses TPM technology (Trusted Platform Module), a cryptochip integrated into a micro SD card (the card goes into the micro SD slot of the smartphone). This hardware piece is designed to generate, store, manage, use and PROTECT encryption keys. The cryptochip is designed to be very sensitive on purpose. That means the information can't be retrieved from the chip (it is not readable by design). If you try to hack the cryptochip - with an oscilloscope, or put it under an electro-microscope, try to freeze and remove it - it damages the chip and all the information it stores is lost immediately. This is the only proven technology today that can protect encryption keys (More on TPM technology: 5 functions of TPM you did not know about).

Interesting: One of an early version of cryptochips was hacked by Cristopher Tarnovsky in 2010. The hack required very high level of expertise and physical possession of the chip. This hack does not work anymore with the new hardwares.

What about stealing the encryption keys?

Good question. There are some companies that use cryptochip (they call it security card or trustchip, this is the very same thing) and put the keys into the chip at production. The keys are safe inside the cryptochip, it is no question, but can be compromised BEFORE they put it into the chip.

Secfone has its own method. Secfone does not put keys into the cryptochip, but uses cryptochip's functions to generate the keys for itself at production. What does it mean?

  1. Keys needed to decrypt the information that arrives to the device NEVER leave the safe storage of cryptochip.
  2. Keys can not be stolen from the factory or from a sysadmin.
  3. Nobody knows the keys (producer of the cryptocard, Secfone, the customer, nobody)

Interesting: Cryptochip is a military-grade technology under special export regulations. Strict legislation apply to keep information on who possesses the technology. It can not be exported to "sensitive" countries. 

Now the keys are safe. However, there are more layers of security in Secfone, I will write a post about them soon.

Thanks for reading. If you found this blog post interesting, please spread the word.

Wednesday, December 11, 2013

Military Technology Protects European Companies - Press Release

NSA scandals and news have drawn attention away from corporate spying, but according to industry experts, this issue continues to cost businesses billions of euros a year. Be Sure Europe LLP has launched online presale program and made Secfone's military-grade, encrypted mobile communication solution used by several governmental and military organizations obtainable for all European companies.



Manchester, UK (PRWEB UK) 11 December 2013

Be Sure Europe LLP has made Lichtenstein based Secfone’s eavesdrop-proof, encrypted mobile communication solution obtainable for all European companies. The online presale program has been launched to provide preliminary access to the online ordering system from Be Sure Europe LLP.

According to a Reuters article published November 13, 2013, Hans-Georg Maassen, the President of the Federal Office for the Protection of the Constitution in Germany, stated that corporate spying has been estimated to cost businesses over 50 billion euros a year in Germany alone. Companies are becoming more aware of this issue, and are looking for solutions to the problem. There are several tools on the market that claim to help these companies protect themselves, but when it comes to encrypted mobile communication, companies have traditionally had to compromise due to the lack of eavesdrop-proof solutions. Secfone’s communication technology offers a solution to this problem.

All software based encryption solutions share the very same and serious problem. The encryption keys that are used to protect the communication can be easily compromised. The encryption solutions built around micro SD security cards or cryptocards can stop this problem from occurring because they have special built in hardware that protects the keys. However, this type of card and protection is just an element of a tap-free system, and cannot guarantee that no eavesdropping will occur. Cracking the encryption for eavesdropping on a smartphone is still possible even if the protection being used is a micro SD security card.

Secfone offers triple-level protection. It goes beyond a hardware-based key protection by utilizing a unique encoding method, along with additional protection against spyware and malware. This technology, which has previously only been available to military professionals, provides protection within a closed, encrypted, global communication network (Manageable Virtual Closed Network, MVCN). Their patented encoding method, a cryptochip integrated into a micro SD card, and the Secfone protection against spyware and malware combine to provide clients with the highest level of security possible.

The pricing for corporate subscriptions to Secfone is for 55 €/month (with 2 years contract, 300 € one-time fee applies to the micro SD cryptocard).



About Secfone: Secfone was launched as a start-up company in the early 2000s, and is a secure communication system supplier for governmental organizations and military. The company built the first eavesdrop-proof smartphone by implementing its patented encoding method on Android and by being the first to use the micro SD card for mobile communication security.

About Be Sure Europe LLP: BeSure Europe LLP is the official Secfone distributor.

Original Press Release: